From patchwork Fri Jan 27 13:05:38 2023 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Xim X-Patchwork-Id: 49381 Return-Path: Delivered-To: ouuuleilei@gmail.com Received: by 2002:adf:eb09:0:0:0:0:0 with SMTP id s9csp825893wrn; Fri, 27 Jan 2023 05:13:36 -0800 (PST) X-Google-Smtp-Source: AMrXdXtmxsGM/P0GP6uIE3II4CnKrKqQOxu51IZDdmzld80sjsAHevYpG7CJZ+iRMYluNKoJGU2g X-Received: by 2002:a17:907:8b98:b0:84d:44dd:e03a with SMTP id tb24-20020a1709078b9800b0084d44dde03amr47035116ejc.57.1674825216108; Fri, 27 Jan 2023 05:13:36 -0800 (PST) ARC-Seal: i=1; a=rsa-sha256; t=1674825216; cv=none; d=google.com; s=arc-20160816; b=zWFi4tpFNBCjm3uTmC6OTR0KP5Oz12r3/KHG+RIaRfIB3NTXQotPZC2iX88hJP38Ma 6D+kDC0nX77yG7IfGgcj4IIk7s3z+OyJxPASaPjo7i/3bULGnQr93du7XvQoqvzkEPh7 mUlH35tzRHdeuS/5nwfVitGgSNU5XC4DP0D+S/Oi25vC/B9eE78xITKvLpb/se0MJ5Ms lQ8eih8q8HG96Ea3SgmknxL7tFZfyHlZSW7fUFzRa3AP/nWcJ0Qqzj3PbdPjgk5vkfNr 9wUistUDusB31fF8162qFGBKLz/ez321JLf9LBheKyW/o1CFvXa80aMZL91/V10rAwq+ ewGg== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:content-transfer-encoding:mime-version :references:in-reply-to:message-id:date:subject:cc:to:from; bh=Ov1UwlLQS46MUcGKOfivdrMjN87yhnKQ9gjrNoMLUbM=; b=YYnx+gHi0zPReK0UaLQ1MqOPKYOiaioUV3fV2VfkIypQ5LX+/4YYY2fCyM6KRAdwIu laZfkBPOLC7+2/D+ruNP7S83ilTLi7qql/QqcPpjv5M3NPcZSH9TI4yxoJgMWy9xnlIY 5q2kHw24Z0V3s2FwMkpPqK0o1NheCOSBIgJ/Qn0rLRqTtSgHbm5vtwROD9sFehXTkL9d sZ5GPYPopdq2WiUlVEmMxEgrmCdM4fxD15Fc2IzPhlxdjnlK17V0XFeD0wgAZSDgvbZI JOhyVJwprxclc+pm0xPudOtRRjh3m/kela907F1SAy30rmqt30sMm9ayTGGKK/JESc2S siAg== ARC-Authentication-Results: i=1; mx.google.com; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org Received: from out1.vger.email (out1.vger.email. [2620:137:e000::1:20]) by mx.google.com with ESMTP id zu24-20020a17090708d800b00829cbd5f6f2si4259379ejb.498.2023.01.27.05.13.12; Fri, 27 Jan 2023 05:13:36 -0800 (PST) Received-SPF: pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) client-ip=2620:137:e000::1:20; Authentication-Results: mx.google.com; spf=pass (google.com: domain of linux-kernel-owner@vger.kernel.org designates 2620:137:e000::1:20 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S234028AbjA0NGo (ORCPT + 99 others); Fri, 27 Jan 2023 08:06:44 -0500 Received: from lindbergh.monkeyblade.net ([23.128.96.19]:47622 "EHLO lindbergh.monkeyblade.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S234520AbjA0NGb (ORCPT ); Fri, 27 Jan 2023 08:06:31 -0500 Received: from cstnet.cn (smtp80.cstnet.cn [159.226.251.80]) by lindbergh.monkeyblade.net (Postfix) with ESMTP id B3CFF7D6CA for ; Fri, 27 Jan 2023 05:06:28 -0800 (PST) Received: from cgk-Precision-3650-Tower.. (unknown [219.141.235.82]) by APP-01 (Coremail) with SMTP id qwCowADX3Eg9zNNjDyF3Ag--.52827S14; Fri, 27 Jan 2023 21:06:10 +0800 (CST) From: Chen Guokai To: paul.walmsley@sifive.com, palmer@dabbelt.com, aou@eecs.berkeley.edu, rostedt@goodmis.org, mingo@redhat.com, sfr@canb.auug.org.au Cc: linux-riscv@lists.infradead.org, linux-kernel@vger.kernel.org, liaochang1@huawei.com Subject: [PATCH v6 10/13] riscv/kprobe: Add instruction boundary check for RVI/RVC hybrid kernel Date: Fri, 27 Jan 2023 21:05:38 +0800 Message-Id: <20230127130541.1250865-11-chenguokai17@mails.ucas.ac.cn> X-Mailer: git-send-email 2.34.1 In-Reply-To: <20230127130541.1250865-1-chenguokai17@mails.ucas.ac.cn> References: <20230127130541.1250865-1-chenguokai17@mails.ucas.ac.cn> MIME-Version: 1.0 X-CM-TRANSID: qwCowADX3Eg9zNNjDyF3Ag--.52827S14 X-Coremail-Antispam: 1UD129KBjvJXoW7uF4rWF15GFyUuFWrXF1UWrg_yoW8Wry8pF s8Cw45JrWrXw47GrySyw48X34SvF4kXr4aqFW7GFyrG34UXr45Xana9rWUtF98Kr9Y9r13 ZF15try0kry7A37anT9S1TB71UUUUUUqnTZGkaVYY2UrUUUUjbIjqfuFe4nvWSU5nxnvy2 9KBjDU0xBIdaVrnRJUUUPKb7Iv0xC_Cr1lb4IE77IF4wAFF20E14v26rWj6s0DM7CY07I2 0VC2zVCF04k26cxKx2IYs7xG6rWj6s0DM7CIcVAFz4kK6r1j6r18M28IrcIa0xkI8VA2jI 8067AKxVWUAVCq3wA2048vs2IY020Ec7CjxVAFwI0_Xr0E3s1l8cAvFVAK0II2c7xJM28C jxkF64kEwVA0rcxSw2x7M28EF7xvwVC0I7IYx2IY67AKxVW8JVW5JwA2z4x0Y4vE2Ix0cI 8IcVCY1x0267AKxVW8Jr0_Cr1UM28EF7xvwVC2z280aVAFwI0_Gr1j6F4UJwA2z4x0Y4vE x4A2jsIEc7CjxVAFwI0_Gr1j6F4UJwAac4AC62xK8xCEY4vEwIxC4wAS0I0E0xvYzxvE52 x082IY62kv0487Mc02F40EFcxC0VAKzVAqx4xG6I80ewAv7VC0I7IYx2IY67AKxVWUJVWU GwAv7VC2z280aVAFwI0_Jr0_Gr1lOx8S6xCaFVCjc4AY6r1j6r4UM4x0Y48IcxkI7VAKI4 8JMxkIecxEwVAFwVW5GwCF04k20xvY0x0EwIxGrwCFx2IqxVCFs4IE7xkEbVWUJVW8JwC2 0s026c02F40E14v26r1j6r18MI8I3I0E7480Y4vE14v26r106r1rMI8E67AF67kF1VAFwI 0_Jw0_GFylIxkGc2Ij64vIr41lIxAIcVC0I7IYx2IY67AKxVW8JVW5JwCI42IY6xIIjxv2 0xvEc7CjxVAFwI0_Gr1j6F4UJwCI42IY6xAIw20EY4v20xvaj40_Jr0_JF4lIxAIcVC2z2 80aVAFwI0_Gr0_Cr1lIxAIcVC2z280aVCY1x0267AKxVW8Jr0_Cr1UYxBIdaVFxhVjvjDU 0xZFpf9x07jF_M3UUUUU= X-Originating-IP: [219.141.235.82] X-CM-SenderInfo: xfkh0w5xrntxyrx6ztxlovh3xfdvhtffof0/1tbiCgsEE2PTtMIZxQAAsM X-Spam-Status: No, score=-1.9 required=5.0 tests=BAYES_00,RCVD_IN_MSPIKE_H2, SPF_HELO_PASS,SPF_PASS autolearn=ham autolearn_force=no version=3.4.6 X-Spam-Checker-Version: SpamAssassin 3.4.6 (2021-04-09) on lindbergh.monkeyblade.net Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org X-getmail-retrieved-from-mailbox: =?utf-8?q?INBOX?= X-GMAIL-THRID: =?utf-8?q?1756181525701044548?= X-GMAIL-MSGID: =?utf-8?q?1756181525701044548?= From: Liao Chang Add instruction boundary check to ensure kprobe doesn't truncate any RVI instruction, which leads to kernel crash. Signed-off-by: Liao Chang --- arch/riscv/kernel/probes/kprobes.c | 24 +++++++++++++++++++++++- 1 file changed, 23 insertions(+), 1 deletion(-) diff --git a/arch/riscv/kernel/probes/kprobes.c b/arch/riscv/kernel/probes/kprobes.c index e1856b04db04..91a6b46909cc 100644 --- a/arch/riscv/kernel/probes/kprobes.c +++ b/arch/riscv/kernel/probes/kprobes.c @@ -49,11 +49,33 @@ static void __kprobes arch_simulate_insn(struct kprobe *p, struct pt_regs *regs) post_kprobe_handler(p, kcb, regs); } +bool __kprobes riscv_insn_boundary_check(unsigned long paddr) +{ +#if defined(CONFIG_RISCV_ISA_C) + unsigned long size = 0, offs = 0, len = 0, entry = 0; + + if (!kallsyms_lookup_size_offset(paddr, &size, &offs)) + return false; + + /* + * Scan instructions from function entry ensure the kprobe address + * is aligned with RVI or RVC boundary. + */ + entry = paddr - offs; + while ((entry + len) < paddr) + len += GET_INSN_LENGTH(*(kprobe_opcode_t *)(entry + len)); + return (entry + len) == paddr; +#else + return true; +#endif +} + int __kprobes arch_prepare_kprobe(struct kprobe *p) { unsigned long probe_addr = (unsigned long)p->addr; - if (probe_addr & 0x1) + /* for RVI/RCV hybrid kernel, it needs instruction boundary check */ + if ((probe_addr & 0x1) || !riscv_insn_boundary_check(probe_addr)) return -EILSEQ; /* copy instruction */